AI Training Data Provenance Checker
Regime

UK GDPR: what it asks of a training dataset list

When the company is established in the UK, or processes personal data of people in the UK: the same lines under the UK regime, with Article 8A deciding whether reuse for a new purpose is compatible. The UK GDPR trigger is separate from the GDPR one.

Cited when the UK GDPR trigger is ticked: established in the UK, or processing personal data of people in the UK.

Three kinds of data, three conditions

Findings that cite it

FindingClause
Origin not recordedUK GDPR Art. 30
Personal data with no lawful basis recorded, or reused from another purposeUK GDPR Art. 6
UK GDPR Art. 8A
UK GDPR Art. 5
Article 9, criminal offence or children's data declaredUK GDPR Art. 35
UK GDPR Art. 9
UK GDPR Art. 10
UK GDPR Art. 8
Older than your N-year policy threshold (a threshold you set, not a legal deadline)UK GDPR Art. 5
Content where a label belongsUK GDPR Art. 5
Vendor data with no provider namedUK GDPR Art. 28

Source classes anchored here

35
Source classClause
Claims system extractUK GDPR Art. 5
UK GDPR Art. 8A
UK GDPR Art. 30
Policy and underwriting systemUK GDPR Art. 5
UK GDPR Art. 8A
UK GDPR Art. 30
CRM exportUK GDPR Art. 5
UK GDPR Art. 8A
UK GDPR Art. 30
ERP and finance systemUK GDPR Art. 5
UK GDPR Art. 8A
UK GDPR Art. 30
HR records and staff surveysUK GDPR Art. 5
UK GDPR Art. 8A
UK GDPR Art. 30
Service desk and ticketingUK GDPR Art. 5
UK GDPR Art. 8A
UK GDPR Art. 30
Application logs and telemetryUK GDPR Art. 5
UK GDPR Art. 8A
UK GDPR Art. 30
Internal document storeUK GDPR Art. 5
UK GDPR Art. 8A
UK GDPR Art. 30
Email archiveUK GDPR Art. 5
UK GDPR Art. 8A
UK GDPR Art. 30
Data warehouse or lake extractUK GDPR Art. 5
UK GDPR Art. 8A
UK GDPR Art. 30
Internal, system not namedUK GDPR Art. 5
UK GDPR Art. 8A
UK GDPR Art. 30
Support and call transcriptsUK GDPR Art. 6
UK GDPR Art. 7
UK GDPR Art. 8A
Chat logsUK GDPR Art. 6
UK GDPR Art. 7
UK GDPR Art. 8A
Reviews on your own siteUK GDPR Art. 6
UK GDPR Art. 7
UK GDPR Art. 8A
Survey and complaint free textUK GDPR Art. 6
UK GDPR Art. 7
UK GDPR Art. 8A
Call recordingsUK GDPR Art. 6
UK GDPR Art. 7
UK GDPR Art. 8A
Licensed vendor datasetUK GDPR Art. 14
UK GDPR Art. 28
Data broker listUK GDPR Art. 14
UK GDPR Art. 28
Annotation vendor outputUK GDPR Art. 14
UK GDPR Art. 28
Licensed image or media libraryUK GDPR Art. 14
UK GDPR Art. 28
Credit reference extractUK GDPR Art. 14
UK GDPR Art. 28
Government open dataUK GDPR Art. 14
Academic or research datasetUK GDPR Art. 14
Open benchmarkUK GDPR Art. 14
Public register or recordsUK GDPR Art. 14
Open source codeUK GDPR Art. 14
Forum postsUK GDPR Art. 14
UK GDPR Art. 6
News articlesUK GDPR Art. 14
UK GDPR Art. 6
Social media postsUK GDPR Art. 14
UK GDPR Art. 6
General web crawlUK GDPR Art. 14
UK GDPR Art. 6
Specific website scrapeUK GDPR Art. 14
UK GDPR Art. 6
Data shared under an agreementUK GDPR Art. 14
UK GDPR Art. 28
Joint venture dataUK GDPR Art. 14
UK GDPR Art. 28
Reinsurer, broker or bank feedUK GDPR Art. 14
UK GDPR Art. 28
Industry consortium dataUK GDPR Art. 14
UK GDPR Art. 28

UK GDPR: every clause cited

11 of the 44 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

UK GDPR Art. 5Principles relating to processing of personal data

Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.

What an auditor asks to see: Records showing each principle applied to each processing activity (purpose, minimisation and retention decisions); Retention schedule with review and deletion evidence; Accountability framework with owners for each principle
What an auditor will probe: Purposes recorded after collection or described too broadly to test compatibility; Retention periods set but never enforced; Assuming a compatible further purpose needs no lawful basis of its own
Source: UK GDPR
UK GDPR Art. 6Lawfulness of processing

Processing is lawful only if at least one basis applies: consent for specific purposes, contract with the data subject, legal obligation, vital interests, a public task laid down in domestic law or relevant international law (section 9A of the 2018 Act), a recognised legitimate interest, or legitimate interests not overridden by the data subject's interests, rights and freedoms (particularly where the data subject is a child). Neither legitimate-interest basis is open to public authorities performing their tasks. A recognised legitimate interest (Article 6(1)(ea)) applies only where a condition in Annex 1 is met: disclosure on request to a body that states it needs the data for a public task, national security, public security or defence, responding to an emergency, detecting or preventing crime or prosecuting offenders, and safeguarding a vulnerable individual (under 18, or 18 or over and at risk); no balancing test is required for these. Article 6(11) gives direct marketing, intra-group transmission for internal administration and network and information security as examples of processing that may be necessary for legitimate interests, which still need the balancing test.

What an auditor asks to see: Lawful basis recorded per processing purpose; Legitimate interests assessments for Article 6(1)(f) processing; Annex 1 condition and the requesting body's written statement kept for each recognised legitimate interest disclosure
What an auditor will probe: Treating the Article 6(11) examples as automatically lawful without a balancing test; Public authorities relying on legitimate interests for their core tasks; Recognised legitimate interest claimed where no Annex 1 condition fits
Source: UK GDPR
UK GDPR Art. 7Conditions for consent

Where processing rests on consent the controller must be able to show the data subject consented. A consent request inside a written declaration covering other matters must be clearly distinguishable, intelligible, easily accessible and in plain language, and any part that infringes the Regulation does not bind. The data subject may withdraw consent at any time, must be told so before consenting, and withdrawing must be as easy as giving consent; withdrawal does not undo earlier lawful processing. Whether consent is freely given takes utmost account of whether a contract or service is made conditional on consent to processing the contract does not need. Consent to an area of scientific research counts as consent where the conditions in Article 4(6) are met.

What an auditor asks to see: Consent records showing who consented, when, to what and how; Consent wording and withdrawal mechanism screenshots; Review of bundled consent in terms and conditions
What an auditor will probe: Consent bundled into terms of service; Withdrawal harder than giving consent (for example phone only); No record able to prove a given individual's consent
Source: UK GDPR
UK GDPR Art. 8Conditions applicable to a child's consent in relation to information society services

Where consent is the basis for offering an information society service directly to a child, processing is lawful for a child aged 13 or over; below 13 it is lawful only with consent given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts, with available technology, to verify that authorisation. Preventive or counselling services are excluded. Since 29 April 2026 (Children's Wellbeing and Schools Act 2026) the Secretary of State may by regulations raise the age to any age up to 16, for all or specified services, and Article 8ZA lets regulations impose age verification requirements; no such regulations are recorded in the held text.

What an auditor asks to see: Age assurance approach and records for services offered directly to children; Parental consent verification procedure for under-13 users; Assessment of whether the service is an information society service offered directly to children
What an auditor will probe: Self-declared age accepted with no further assurance where risk is high; No mechanism to verify parental authorisation; Counselling services wrongly made subject to parental consent
Source: UK GDPR
UK GDPR Art. 8APurpose limitation: further processing

Whether processing for a new purpose is compatible with the purpose of collection is decided by weighing, among other things, the link between the purposes, the context of collection and the relationship with the data subject, the nature of the data (special category or criminal offence data), the possible consequences, and safeguards such as encryption or pseudonymisation. Further processing is treated as compatible where the data subject consents to a specified, explicit and legitimate new purpose; where it is research, archiving or statistics under Article 84B; where it ensures or demonstrates compliance with Article 5(1); where an Annex 2 condition is met (disclosure on request for a public task, archiving disclosures of consent-based data, public security, emergencies, crime, vital interests, safeguarding vulnerable individuals, tax, legal obligations); or where it is necessary for an Article 23(1)(c) to (j) objective and authorised by law. Data collected on consent may be reused only with fresh consent or for compliance, or under Annex 2 or an authorised objective where consent cannot reasonably be sought.

What an auditor asks to see: Compatibility assessments for each new use of existing data; Annex 2 condition recorded for reuse relying on it; Evidence that consent-based data was not reused beyond Article 8A(4)
What an auditor will probe: Reuse of consent-based data for analytics without fresh consent; No documented compatibility test before repurposing data; Relying on Annex 2 without the request or legal duty it requires
Source: UK GDPR
UK GDPR Art. 9Processing of special categories of personal data

Processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person uniquely, health data, or data about sex life or sexual orientation is prohibited unless a lawful basis under Article 6 applies together with a condition in Article 9(2): explicit consent, employment, social security and social protection law, vital interests where consent is impossible, not-for-profit bodies' members, data manifestly made public, legal claims and courts, substantial public interest, health and social care, public health, or archiving, research and statistics under Article 84B. Where the condition needs a basis in domestic law, section 10 and Schedule 1 of the 2018 Act supply it (often with an appropriate policy document); health and social care processing must be by or under the responsibility of a professional bound by secrecy. Article 11A lets regulations add descriptions of processing to the prohibition and set which exceptions apply to them.

What an auditor asks to see: Article 9 condition and, where required, the Schedule 1 condition of the 2018 Act recorded per processing; Appropriate policy document where Schedule 1 requires one; Explicit consent records where that is the condition
What an auditor will probe: Biometric processing for identification without an Article 9 condition; Relying on substantial public interest without the Schedule 1 condition and policy document; Health data processed outside the professional-secrecy safeguard
Source: UK GDPR
UK GDPR Art. 10Processing of personal data relating to criminal convictions and offences

Personal data about criminal convictions, offences or related security measures, processed on an Article 6 basis, may be processed only under the control of official authority or where authorised by domestic law or relevant international law with appropriate safeguards; section 10(5) and Schedule 1 of the 2018 Act supply the domestic-law conditions and section 11(2) defines the data to include allegations, proceedings and sentencing. A comprehensive register of criminal convictions may be kept only under official authority.

What an auditor asks to see: Schedule 1 condition relied on for each criminal offence data processing (for example employment vetting); Appropriate policy document covering the processing; Access controls around criminal records checks
What an auditor will probe: Collecting criminal record information for roles without a Schedule 1 condition; Retaining disclosure certificates longer than needed; Treating allegations as outside the Article
Source: UK GDPR
UK GDPR Art. 14Information to be provided where personal data have not been obtained from the data subject

Where data come from elsewhere the controller must give the Article 13 information plus the categories of data and the source (including whether publicly accessible), within a reasonable period and at the latest one month after obtaining the data, or at first communication with the data subject, or when first disclosing to another recipient, and must tell the data subject before further processing for a new purpose. The duty falls away where the data subject already has the information, where obtaining or disclosure is expressly required by domestic law with appropriate protections, where professional secrecy requires confidentiality, where providing the information is impossible or would involve disproportionate effort (judged by the number of data subjects, the age of the data and the safeguards), or where it would render impossible or seriously impair the purposes; a controller relying on the last two must protect the data subject's interests, including by publishing the information.

What an auditor asks to see: Notices sent to data subjects whose data came from third parties, with dates; Disproportionate effort assessments and the published information; Record of data sources per data set
What an auditor will probe: Enriched or purchased data used with no notice to the people concerned; Disproportionate effort claimed without a written assessment; Notice sent later than one month after receipt
Source: UK GDPR
UK GDPR Art. 28Processor

A controller may use only processors giving sufficient guarantees of appropriate measures. A processor may not engage a sub-processor without prior specific or general written authorisation, and under general authorisation must notify changes so the controller can object. Processing must be governed by a written contract or legal act setting out the subject matter, duration, nature, purpose, data types, data subjects and the controller's rights and obligations, and requiring the processor to act only on documented instructions (including on transfers), bind its staff to confidentiality, take Article 32 measures, respect sub-processing conditions, assist with rights requests and with Articles 32 to 36, delete or return data at the end, and provide information and allow audits, informing the controller if an instruction infringes the law. Sub-processors carry the same obligations and the processor stays liable for them. The Commissioner may adopt standard contractual clauses; a processor that determines purposes and means is treated as a controller.

What an auditor asks to see: Article 28 compliant processing agreements for every processor; Sub-processor list with authorisation and change notices; Processor due diligence and audit records
What an auditor will probe: Processors engaged on standard terms lacking the Article 28(3) clauses; Sub-processors added without notice; No evidence data were deleted or returned at contract end
Source: UK GDPR
UK GDPR Art. 30Records of processing activities

Each controller (and representative) must keep a written, including electronic, record of its processing with its name and contacts, purposes, categories of data subjects and data, recipients, transfers abroad with Article 49(1) second-subparagraph safeguards documented, erasure time limits where possible, and a general description of security measures. Each processor must keep a record of the categories of processing it carries out for each controller, transfers and security measures. Records must be made available to the Commissioner on request. Organisations with fewer than 250 employees are exempt unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal offence data.

What an auditor asks to see: Record of processing activities covering every required field; Processor record per controller; Evidence of periodic review of the records
What an auditor will probe: Records not updated as systems change; Small organisations claiming the exemption despite regular processing; Security measures described only generically
Source: UK GDPR
UK GDPR Art. 35Data protection impact assessment

Before processing likely to result in a high risk, particularly with new technologies, the controller must assess the impact, seeking the DPO's advice. A DPIA is required in particular for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale systematic monitoring of public areas, and for the kinds of processing on the Commissioner's published list. The DPIA must contain a description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures to address them; approved codes are taken into account, data subjects' views sought where appropriate, and the assessment reviewed when the risk changes.

What an auditor asks to see: DPIA screening records for new processing; Completed DPIAs with the four required elements and DPO advice; Review records when processing changes
What an auditor will probe: DPIA done after launch; Screening not documented; Commissioner's list of high-risk processing ignored
Source: UK GDPR